|Package(s):||bugzilla||CVE #(s):||CVE-2006-5453 CVE-2006-5454 CVE-2006-5455|
|Created:||November 10, 2006||Updated:||August 28, 2007|
|Description:||Bugzilla has the following vulnerabilities:
Input data passed to various fields is not properly sanitized before being passed back to users.
Users can gain unauthorized access to read attachment descriptions while using diff mode.
HTTP GET and HTTP POST requests can be used to perform unauthorized actions due to improper verification.
Input that is passed to showdependencygraph.cgi is not properly sanitized before being returned to users.
Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds